Cyber Security Manager - Offensive Security at EY
Trivandrum, Kerala, India · Full Time
Be the first to apply
- Experience
- 10–14 yrs
- Salary
- —
- Openings
- 1
- Posted
- 4 weeks ago
- Work mode
- In office
- Education
- Bachelor's or Master's degree in Cyber Security, Information Technology, Computer Science or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About EY and the Opportunity
EY is a global leader dedicated to shaping futures with confidence by fostering diverse teams and supporting career growth. Join us to advance your career and contribute to building a better working world. We seek a Manager specializing in Offensive Security within our Cyber Security team, focusing on Red Teaming, Cloud-native Vulnerability Assessment and Penetration Testing (VAPT), and DevSecOps security assurance. Exposure to AI, Machine Learning (ML), and GenAI security assessments is a valuable addition due to growing AI adoption.
Role Overview
As a key member of our Cyber Technology Consulting practice, you will lead offensive security engagements for clients primarily across the MENA region, spanning multiple sectors such as Financial Services, Government and Public Sector, Energy, Telecom, Healthcare, and Digital-native enterprises. This role combines deep technical expertise with strategic advisory and large-scale transformation, contributing to the growth of our Offensive Security practice.
Key Responsibilities
- Lead comprehensive offensive security engagements including network and infrastructure penetration tests, web and mobile application security assessments, and API security evaluations across REST, SOAP, GraphQL, and microservices.
- Plan and conduct red team, adversary simulation, and assumed breach exercises to evaluate organizational detection and response capabilities.
- Drive purple teaming engagements to align offensive findings with defensive enhancements involving SOC, detection engineering, and incident response teams.
- Perform cloud offensive security assessments across AWS, Azure, and GCP environments, evaluating IAM configurations, network security, storage, containerization, serverless functions, and DevSecOps pipelines.
- Identify cloud misconfigurations, conduct privilege escalation analysis, investigate insecure pipelines and exposed secrets, and assess lateral movement threats in hybrid and cloud-native landscapes.
- Test security of cloud-native architectures such as Kubernetes, infrastructure as code, container images, and CI/CD pipelines to uncover vulnerabilities in the software development lifecycle.
- Validate Cloud Security Posture Management (CSPM), Cloud Native Application Protection Platform (CNAPP) controls, and identify configuration gaps and risks.
- Deliver AI and GenAI security assessments including prompt injection, adversarial input risks, model misuse, data leakage, and governance considerations.
- Translate technical vulnerabilities into actionable business risks with impact analysis and prioritized remediation plans.
- Advise CISOs, CIOs, security leaders, and engineering teams with tailored communication of security findings for both technical and non-technical stakeholders.
- Assist clients in developing offensive security roadmaps, maturity models, and remediation strategies aligning with industry standards.
- Enhance the Offensive Security practice through methodology development, creating reusable testing assets, standardizing delivery processes, and supporting marketing efforts such as RFP responses and thought leadership content.
- Keep abreast of evolving cybersecurity threats, particularly advanced attacker techniques, new API and cloud-native attack vectors, and AI/ML related vulnerabilities.
- Manage and mentor a team of consultants to develop deep offensive security skills, ensure quality delivery, support continuous learning, and foster a collaborative team culture.
Required Qualifications and Experience
- Bachelor’s or Master’s degree in Cyber Security, Information Technology, Computer Science, or a related field.
- 10 to 14 years of professional experience in Cyber Security, with a strong emphasis on Offensive Security and advanced VAPT.
- Expert knowledge of OWASP Top 10, OWASP API Security Top 10, SANS Top 25, and MITRE ATT&CK frameworks.
- Hands-on experience conducting network, application, API, and cloud penetration testing and red team exercises.
- Proven expertise in cloud security assessments across AWS, Azure, and GCP environments, including DevSecOps and CI/CD security validation.
- Strong reporting, documentation, and presentation abilities.
- Experience working in consulting or professional services with client and engagement management.
- Capability to operate in a global and multicultural environment; willingness to travel within the MENA region.
- Relevant security certifications such as OSCP, OSEP, OSCE, CRTO, GWAPT, GPEN, or equivalents.
Desirable Expertise and Exposure
- Advanced red and purple teaming methodologies.
- API security and cloud offensive security assessments.
- Security testing for AI and large language models (LLMs).
- Container, Kubernetes, and DevSecOps pipeline security.
- Experience with breach and attack simulation (BAS) tools and platforms.
- Validation and engineering for Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) systems.
- Familiarity with regulatory and industry frameworks applicable to the MENA region.
Desired Personal Attributes
- A proactive growth mindset and a passion for offensive security disciplines.
- The ability to integrate deep technical expertise with business understanding.
- Strong client-oriented attitude and relationship-building skills.
- Collaborative problem-solving ability and innovative thinking.
- A commitment to quality, ethics, and continuous improvement.
About EY
EY strives to build a better working world by delivering value to clients, communities, and the environment while upholding trust within capital markets. Leveraging data, AI, and advanced technologies, EY collaborates across assurance, consulting, tax, strategy, and transaction services in over 150 countries globally.
Minimum education
Master's Degree